Maven vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2022-36100Criticalorg.xwiki.platform:xwiki-platform-tag-ui: XWiki Platform Applications Tag and XWiki Platform Tag UI vulnerable to Eval InjectionCVE-2022-36092Highorg.xwiki.platform:xwiki-platform-oldcore: XWiki Platform Old Core vulnerable to Authentication Bypass Using the Login ActionCVE-2022-36093Highorg.xwiki.platform:xwiki-platform-web-templates: XWiki Platform Web Templates vulnerable to Unauthorized User Registration Through the Distribution WizardCVE-2022-36094Highorg.xwiki.platform:xwiki-platform-web: XWiki Platform Web Parent POM vulnerable to XSS in the attachment historyCVE-2022-25897Highorg.eclipse.milo:sdk-server: Eclipse Milo vulnerable to Resource Exhaustion (Denial of Service)CVE-2022-37724Mediumwonder:wonder: Project Wonder WebObjects vulnerable to Arbitrary HTTP Header Injection and Cross-site ScriptingCVE-2022-1278Highorg.wildfly.bom:wildfly: WildFly vulnerable to Insecure Default Initialization of ResourceCVE-2022-40634Highorg.craftercms:crafter-studio: CrafterCMS Crafter Studio Improperly Controls Dynamically-Managed Code ResourcesCVE-2022-40635Highorg.craftercms:craftercms: CrafterCMS OS Command Injection vulnerabilityCVE-2022-37734Highcom.graphql-java:graphql-java: graphql-java vulnerable to Denial of Service via GraphQL query that consumes CPU resourcesCVE-2022-37767Criticalio.pebbletemplates:pebble: Pebble Templates protection mechanism bypass can lead to arbitrary code executionCVE-2022-39135Criticalorg.apache.calcite:calcite-core: Apache Calcite before 1.32.0 vulnerable to potential XML External Entity (XXE) attackCVE-2022-26049Highcom.diffplug.gradle:goomph: Goomph before 3.37.2 allows malicious zip file to write contents to arbitrary locationsCVE-2022-28220Highorg.apache.james:james-server: Apache James vulnerable to buffering attackCVE-2022-25914Criticalcom.google.cloud.tools:jib-core: com.google.cloud.tools:jib-core vulnerable to Remote Code Execution (RCE)CVE-2022-36663Criticalorg.gluu:oxauth-common: Gluu Oxauth before v4.4.1 vulnerable to Server-Side Request Forgery attacks via a crafted request_uri parameterCVE-2022-38751Mediumorg.yaml:snakeyaml: snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds WriteCVE-2022-38369Mediumorg.apache.iotdb:iotdb-server: Apache IoTDB Session Fixation vulnerabilityCVE-2022-38750Mediumorg.yaml:snakeyaml: snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds WriteCVE-2022-38749Mediumorg.yaml:snakeyaml: snakeYAML before 1.31 vulnerable to Denial of Service due to Out-of-bounds WriteCVE-2022-38752Mediumorg.yaml:snakeyaml: snakeYAML before 1.32 vulnerable to Denial of Service due to Out-of-bounds WriteCVE-2022-38370Highorg.apache.iotdb:iotdb-grafana-connector: Apache IoTDB grafana-connector contains an interface without authorizationCVE-2022-37435Highorg.apache.shenyu:shenyu-common: Apache ShenYu Admin has insecure permissionsCVE-2022-36033Mediumorg.jsoup:jsoup: jsoup may not sanitize code injection XSS attempts if SafeList.preserveRelativeLinks is enabledCVE-2022-37022Highorg.apache.geode:geode-core: Apache Geode versions deserialization of untrusted datawhen using JMX over RMI on Java 11

Stop the waste.
Protect your environment with Kodem.